Executive brief
Roo-Code is a development assistant tool that uses OAuth for user authentication. The application transmits OAuth authorization codes over unencrypted HTTP instead of HTTPS during the authentication callback, allowing attackers on the same network to intercept these credentials and hijack user accounts. An attacker could use ARP spoofing or packet sniffing on a shared WiFi network to capture the authorization code and gain full access to a victim's account and associated data.
Technical details
The vulnerability is a cleartext transmission of sensitive information (CWE-319) in the OAuth callback implementation. The root cause lies in src/integrations/claude-code/oauth.ts where the redirect URI is hardcoded as "http://localhost:54545/callback" instead of using HTTPS. An attacker on the same network can intercept the OAuth authorization code transmitted in cleartext HTTP traffic via ARP spoofing or packet sniffing, then exchange it for an access token to hijack the victim's account. The attack requires the attacker and victim to be on the same network and the victim to initiate OAuth login, but no additional authentication or user interaction beyond that is required. The project is no longer maintained by the vendor, and no patches are available.
Affected products
- RooCodeInc Roo-Code up to 3.51.1
Timeline
- 2026-08-28: disclosed
- exploited: Public proof-of-concept available